CultureAI has released a new report, ‘The State of Enterprise AI Usage: The Illusion of Control‘. This shows that organizations are struggling with AI governance and visibility, with 65% of organizations detecting unauthorised shadow AI. However, it appears that many may be unaware of the extent of the issue, with 72% of surveyed organizations believing that they have full visibility into AI usage.
The research, conducted by Censuswide, features insights from 300 senior technology, security, and risk leaders from across North America and Europe.
The key findings are:
AI adoption is widespread and decentralised
The research found that AI is widely used across teams, with 67% of security leaders reporting wide use across the organization. Currently, AI use is most notably focused on core functions like data analysis and revenue operations (72%), software development and engineering (59%), and customer support (43%). However, the vast majority of respondents (91%) expect AI usage to grow across their entire organization over the next 12 months, with 41% expecting significant growth. However, risk scales with usage. As exposure grows faster than controls, an organization often has little time to prepare, says the report.
The illusion of control
Nearly three-quarters (72%) of respondents report full visibility into AI usage, while 28% report only partial or no visibility. However, nearly two-thirds (65%) of respondents reported detection of unauthorised AI usage (shadow AI). This means that many tools, personal accounts, and embedded AI features remain invisible to traditional controls.
Most organizations express strong confidence in their visibility and governance posture, with formal frameworks, policies, and oversight committees now being common. However, unauthorised AI usage, limited detection, and inconsistent enforcement capabilities remain widespread, creating an illusion of control: governance exists, but behaviour frequently escapes it.
AI risk is recognised, but often underestimated
Leaders consistently identified high-impact concerns such as compliance exposure (56%), data leakage via prompts and uploads (52%), credential compromise (40%), and intellectual property loss (39%). Despite this, nearly half (46%) of respondents rate AI risk as moderate or low. While organizations acknowledge AI risk, these risks are rarely escalated. This apparent contradiction reveals that leaders are not dismissing AI risk, but they are struggling to accurately quantify it in an environment where damage often occurs without an obvious breach, alert, or outage.
AI governance exists, but is not operational
Most organizations have policies, committees, and training in place, but lack mechanisms that operate in real time at the point where AI risk is actually created: prompts, uploads, and embedded AI features inside SaaS tools. Nearly two-thirds (62%) of organizations report they have already implemented a formal AI governance framework, while a further third are actively developing one. Similarly, over two-thirds (67%) say they have established an AI or risk committee with explicit oversight responsibilities. However, this confidence sits alongside clear operational gaps, with 20% of respondents acknowledging that their policies are not actively enforced and more than a third lacking dedicated AI detection capabilities altogether.






